跳至主要内容
申请方案

Trust Center

The compliance answers your procurement team is going to ask.

Published in one place so you do not have to chase them. Certificates of insurance, BAA template, DPA, and sub-processor list available on request.

Request Our Compliance Pack
  • MBE-eligible

    NMSDC certification in progress

  • HIPAA-ready

    BAA available on request

  • Insurance

    GL $2M, E&O $1M, Cyber $1M

  • SOC 2 Type I

    On roadmap, first healthcare client

Posture details

Every dimension procurement asks about.

MBE eligibility

Corpshore Solutions Corporation, our parent, is a certified minority business enterprise candidate. NMSDC certification is in active progress, targeted for completion within the next 12 months. Spend with us counts toward Tier 1 or Tier 2 supplier diversity reporting subject to your program rules.

HIPAA posture

We operate non-clinical healthcare functions only (billing, coding, prior authorization, RCM analytics, patient access, HIM). Workforce trained on HIPAA, ePHI handling, and incident response. BAA available on request. We do not store ePHI outside the client's environment unless contractually required.

SOC 2 Type I

On roadmap, targeted to coincide with our first healthcare client engagement. We will publish the report on this page when complete and notify existing clients via the standard channel.

Insurance

General Liability $2M. Errors and Omissions $1M. Cyber Liability $1M. Certificate of insurance available on request. Renewal date in our standard procurement pack.

Data residency

By default, client data stays in your environment. We access via your tenant under your IAM controls. Where data must reside in our systems (Supabase for form fallback, Zoho CRM for lead management), it is in the regions you specify in the DPA.

GDPR and CCPA posture

DPA available on request. Sub-processor list maintained and shared with active clients. Data subject access requests acknowledged within 72 hours, fulfilled within the statutory window per jurisdiction.

Background checks

All operations staff complete background checks per the local jurisdiction standard. For US-facing engagements, this includes SSN trace, county criminal, federal criminal, and education verification.

Business Continuity Plan

Multi-region delivery footprint provides natural redundancy. Each engagement has a documented BCP including failover delivery center, communication tree, and recovery time targets.

Need the full compliance pack?

We send a single PDF: insurance certificate, BAA template, DPA, sub-processor list, BCP summary, and any vendor questionnaires you require us to complete.

Request Our Compliance Pack